Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Use Microsoft threat intelligence to generate high-fidelity alerts and incidents. Enable the Microsoft Defender Threat Intelligence Analytics rule, a built-in rule in Microsoft Sentinel. This rule matches indicators with Common Event Format (CEF) logs, Windows DNS events, syslog data, and more. It checks for domain and IPv4 threat indicators across these data sources.
Prerequisites
Install one or more supported data connectors. You don't need a premium Microsoft Defender Threat Intelligence license. To connect your data sources, install the right solutions from the Content hub. The following data sources are supported:
- Common Event Format (CEF) via Legacy Agent
- Windows DNS via Legacy Agent (Preview)
- Syslog via Legacy Agent
- Microsoft 365 (formerly, Office 365)
- Azure activity logs
- Windows DNS via AMA
- Advanced Security Information Model (ASIM) Network sessions
For example, depending on your data source, you might use the following solutions and data connectors:
Configure the matching analytics rule
Matching analytics is configured when you enable the Microsoft Defender Threat Intelligence Analytics rule.
Important
Before you enable this rule, install at least one supported data connector and its corresponding Content hub solution. See Prerequisites for the full list of supported data sources.
Under the Configuration section, select the Analytics menu.
Select the Rule templates tab.
In the search window, enter threat intelligence.
Select the Microsoft Defender Threat Intelligence Analytics rule template.
Select Create rule. The rule details are read only, and the default status of the rule is enabled.
Select Review > Create.
Review supported data sources and indicators
Microsoft Defender Threat Intelligence Analytics matches your logs with domain, IP, and URL indicators in the following ways:
- CEF logs ingested into the Log Analytics
CommonSecurityLogtable match URL and domain indicators if populated in theRequestURLfield, and IPv4 indicators in theDestinationIPfield. - Windows DNS logs, where
SubType == "LookupQuery"ingested into theDnsEventstable matches domain indicators populated in theNamefield, and IPv4 indicators in theIPAddressesfield. - Syslog events, where
Facility == "cron"ingested into theSyslogtable matches domain and IPv4 indicators directly from theSyslogMessagefield. - Office activity logs ingested into the
OfficeActivitytable match IPv4 indicators directly from theClientIPfield. - Azure activity logs ingested into the
AzureActivitytable match IPv4 indicators directly from theCallerIpAddressfield. - ASIM DNS logs ingested into the
ASimDnsActivityLogstable match domain indicators if populated in theDnsQueryfield, and IPv4 indicators in theDnsResponseNamefield. - ASIM Network Sessions ingested into the
ASimNetworkSessionLogstable match IPv4 indicators if populated in one or more of the following fields:DstIpAddr,DstNatIpAddr,SrcNatIpAddr,SrcIpAddr,DvcIpAddr.
Triage an incident generated by matching analytics
If the Microsoft Defender Threat Intelligence Analytics rule finds a match, any alerts generated are grouped into incidents.
Use the following steps to triage through the incidents generated by the Microsoft Defender Threat Intelligence Analytics rule:
In the Microsoft Sentinel workspace where you enabled the Microsoft Defender Threat Intelligence Analytics rule, select Incidents, and search for Microsoft Defender Threat Intelligence Analytics.
Any incidents that are found appear in the grid.
Select View full details to view entities and other details about the incident, such as specific alerts.
Here's an example.
Check the severity of the alerts and the incident. Alert severity ranges from
InformationaltoHighbased on how the indicator is matched. For example, an indicator matched with firewall logs that allowed traffic produces a high-severity alert. The same indicator matched with firewall logs that blocked traffic produces a low or medium alert.Alerts are grouped by the indicator they match. For example, all alerts in a 24-hour period that match the
contoso.comdomain are grouped into one incident. The incident severity is based on the highest alert severity.Observe the indicator information. When a match is found, the indicator is published to the Log Analytics
ThreatIntelligenceIndicatorstable, and it appears on the Threat Intelligence page. For any indicators published from this rule, the source is defined asMicrosoft Threat Intelligence Analytics.
Here's an example of the ThreatIntelligenceIndicators table.
Here's an example of searching for the indicators in the management interface.
Get more context from Microsoft Defender Threat Intelligence
Some Microsoft Defender Threat Intelligence indicators also include a link to a related Intel Explorer article. Use this link to get more details about the indicator.
For more information, see Threat analytics in Microsoft Defender XDR.
Related content
To learn more about threat intelligence in Microsoft Sentinel, see the following articles:
- Work with threat indicators in Microsoft Sentinel
- Connect Microsoft Sentinel to STIX/TAXII threat intelligence feeds.
- Connect threat intelligence platforms to Microsoft Sentinel.
- See which TIP platforms, TAXII feeds, and enrichments can be readily integrated with Microsoft Sentinel.